External entropy supply for IoT devices employing a RISC-V Trusted Execution Environment

📅 2026-03-10
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the challenge of generating high-security cryptographic keys on resource-constrained IoT devices, which often lack sufficient entropy sources. The authors propose a scalable, distributed entropy provisioning mechanism based on a RISC-V trusted execution environment (TEE). In this approach, devices leverage minimal initial true entropy or pre-provisioned keys to establish a secure channel and obtain high-quality entropy from a TEE-based server, with optional augmentation from external high-entropy sensors. To the best of the authors’ knowledge, this is the first implementation of a verifiable and scalable remote entropy service within a RISC-V TEE architecture. By integrating remote attestation and secure communication protocols, the scheme effectively enhances the security of IoT key generation. An open-source prototype demonstrates the feasibility and efficacy of constructing a trusted entropy infrastructure on open RISC-V platforms.

Technology Category

Application Domains: Internet of Things, Sensor Networks & Smart CitiesData Mining & Knowledge Management: Representing, Reasoning, and Using Provenance, TrustMachine Learning: Hardware-aware ML

Application Category

Security and Privacy: Large-scale security measurementsSystems and Infrastructure for Web, Mobile and WoT: Energy management for devices in mobile Web and WoT environmentsSemantics and Knowledge: Provenance, trust, security and privacy, and ethical issues in managing semantic data
📝 Abstract
Entropy--a measure of randomness--is compulsory for the generation of secure cryptographic keys; however, Internet of Things (IoT) devices that are small or constrained often struggle to collect suf ficient entropy. In this article, we solve the entropy provisioning problem for a fleet of IoT devices that can generate a limited amount of entropy. We employ a Trusted Execution Environment (TEE) based on RISC-V to create an external entropy service for a fleet of IoT devices. A small measure of true entropy or pre-installed keys can establish initial secure communication. Once connected, devices can request cryptographically strong entropy from a TEE-backed server. RISC-V offers True Random Number Generators (TRNGs) and a TEE for devices to attest that they are receiving reliable entropy. In addition, this solution can be expanded by adding IoT devices with sensors that produce high-quality entropy as additional entropy sources for the RISC-V entropy provider. Our open-source implementation shows that building trusted entropy infrastructure for IoT is both feasible and effective on open RISC-V platforms.
Problem

Research questions and friction points this paper is trying to address.

entropy
IoT devices
cryptographic keys
Trusted Execution Environment
RISC-V
Innovation

Methods, ideas, or system contributions that make the work stand out.

RISC-V
Trusted Execution Environment
Entropy Provisioning
IoT Security
True Random Number Generator
💼 Related Jobs
No related jobs found.
A
Arttu Paju
Tampere University, Tampere, Finland
Alejandro Cabrera Aldaya
Alejandro Cabrera Aldaya
Tampere University
SecurityCryptographySide-channel analysisEmbedded systems
Nicola Tuveri
Nicola Tuveri
Doctoral Researcher, Tampere University
Cryptographyside channelssecurity
J
Juha Savimäki
Tampere University, Tampere, Finland; Unikie Oy, Tampere, Finland
M
Marko Kivikangas
Tampere University, Tampere, Finland
B
Brian McGillion
Technology Innovation Institute (TII), Abu Dhabi, UAE